The Containment Era is here. →Explore

Industry Category

Legal Services

Breach intelligence, attack campaigns, and threat reports targeting the Legal Services sector.

162 threat reports
Page 3 of 14

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Legal Services Threat Reports

Showing 2536 / 162 reports
Understanding the 'WriteOut' Vulnerability in Writer AI Platform
Impact· HIGH

Understanding the 'WriteOut' Vulnerability in Writer AI Platform

In July 2026, a critical session isolation vulnerability, dubbed 'WriteOut,' was discovered in Writer, an enterprise generative AI platform. This flaw allowed attackers to hijack user sessions across different organizations by exploiting the platform's live preview feature. By sharing a malicious preview link, attackers could gain unauthorized access to sensitive data, including private chats, documents, and large language model credentials, without requiring prior access to the victim's organization. ([thehackernews.com](https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html?utm_source=openai)) The 'WriteOut' vulnerability underscores the growing security challenges in AI platforms, particularly concerning tenant isolation and session management. As AI adoption accelerates, ensuring robust security measures to prevent cross-tenant data breaches becomes imperative for organizations relying on such technologies.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Understanding the 2026 Microsoft Device Code Phishing Attack
Impact· MEDIUM

Understanding the 2026 Microsoft Device Code Phishing Attack

In early 2026, a sophisticated phishing campaign exploited Microsoft's OAuth 2.0 Device Authorization Grant flow to compromise user accounts. Attackers initiated the device code authentication process and tricked victims into entering the provided code on Microsoft's legitimate login page, thereby granting unauthorized access without exposing credentials. This method allowed threat actors to bypass multi-factor authentication (MFA) and maintain persistent access to services like Outlook, OneDrive, and Teams by capturing access and refresh tokens. The campaign, active from April to mid-May 2026, targeted Microsoft 365 users through deceptive emails and malicious attachments, leading to significant data breaches and unauthorized account activities. The incident underscores a growing trend of attackers leveraging legitimate authentication mechanisms to bypass traditional security measures. The rise of device code phishing highlights the need for organizations to reassess their security protocols, especially concerning OAuth flows and MFA implementations. As phishing techniques become more sophisticated, continuous monitoring, user education, and the implementation of conditional access policies are crucial to mitigate such threats.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Interpol Impersonation Ransomware Targets Small Businesses in 2026
Impact· HIGH

Interpol Impersonation Ransomware Targets Small Businesses in 2026

In July 2026, a ransomware campaign targeted small businesses across multiple regions, including the US, Europe, Asia, and the Middle East. Attackers impersonated Interpol officials, sending phishing emails that claimed the recipient's organization was under investigation for suspicious activity. These emails urged recipients to download a password-protected archive from Proton Drive, purportedly containing evidence. Upon opening, the archive delivered a ransomware payload disguised as a video file, encrypting local systems and prompting victims to contact the attackers via the Tox messaging platform to negotiate payment. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/attackers-use-interpol-lure-target-small-businesses?utm_source=openai)) This incident underscores the increasing trend of cybercriminals leveraging social engineering tactics to exploit small businesses, which often lack dedicated cybersecurity resources. The campaign highlights the need for heightened awareness and robust security measures to defend against such deceptive attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking
Impact· HIGH

ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking

In July 2026, a sophisticated social engineering attack known as ConsentFix emerged, targeting Microsoft 365 users. This attack exploits users' habitual responses to familiar prompts by presenting a seemingly legitimate authentication process. Victims receive phishing lures that lead them to a fake Microsoft sign-in page, where they are instructed to drag a localhost callback link into their browser. This action inadvertently grants attackers OAuth tokens, enabling unauthorized access to the victim's Microsoft 365 account without requiring passwords or bypassing multi-factor authentication. The attack is particularly insidious as it leverages routine user behaviors, making it difficult to detect and prevent. The ConsentFix attack underscores the evolving nature of cyber threats that exploit user trust and routine actions. As attackers continue to refine their methods, it is imperative for organizations to enhance user education on recognizing sophisticated phishing attempts and to implement robust security measures that can detect and mitigate such deceptive tactics.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ToddyCat's Umbrij Malware: A New Threat to Gmail Security
Impact· HIGH

ToddyCat's Umbrij Malware: A New Threat to Gmail Security

In June 2026, the advanced persistent threat group known as ToddyCat deployed a new malware tool named Umbrij to infiltrate corporate Gmail accounts. Utilizing a technique termed Shadow Token via Remote Debug (STRD), the attackers exploited active user sessions in Chromium-based browsers to obtain OAuth tokens, granting unauthorized access to Gmail and other Google services without requiring user credentials. This method allowed them to read emails, access calendars, and gather data from Google Drive, all while remaining undetected for extended periods. The emergence of Umbrij underscores a significant evolution in cyber-espionage tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. Organizations must reassess their security protocols, particularly concerning API access and browser session management, to mitigate such advanced threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Massive 2026 Data Breach Exposes One Million Passport Records
Impact· HIGH

Massive 2026 Data Breach Exposes One Million Passport Records

In June 2026, a significant data breach exposed nearly one million passport records worldwide. The compromised data originated from an ID verification system used by cannabis dispensaries, where high-value credentials like passports were utilized for authentication. Attackers exploited vulnerabilities in this ancillary system, leading to the unauthorized disclosure of sensitive personal information. This incident underscores the critical need for robust security measures across all systems handling sensitive data, regardless of their primary function. It highlights the risks associated with using high-value credentials in less secure, ancillary systems and the potential for such breaches to have widespread implications.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
INC Ransomware's 2026 Surge: A Growing Threat to Sensitive Sectors
Impact· CRITICAL

INC Ransomware's 2026 Surge: A Growing Threat to Sensitive Sectors

In early 2026, the INC ransomware group, a ransomware-as-a-service (RaaS) operation active since mid-2023, intensified its attacks across various sectors, notably healthcare, education, and government entities. Utilizing double extortion tactics, INC affiliates gained initial access through spear-phishing campaigns and exploitation of vulnerabilities in external services. Once inside, they conducted internal reconnaissance using tools like NETSCAN.EXE and AnyDesk.exe, exfiltrated sensitive data, and deployed ransomware to encrypt systems, pressuring victims into paying ransoms to prevent data leaks. ([explore.ontolocy.com](https://explore.ontolocy.com/intel/intrusion-sets/inc-ransomware-group/?utm_source=openai)) This surge in INC's activities underscores the evolving ransomware landscape, where groups leverage RaaS models to scale operations rapidly. The focus on sectors with sensitive data highlights the critical need for organizations to bolster defenses against such multifaceted threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 'SearchLeak' Vulnerability in Microsoft 365 Copilot (CVE-2026-42824)
Impact· HIGH

Understanding the 'SearchLeak' Vulnerability in Microsoft 365 Copilot (CVE-2026-42824)

In June 2026, a critical vulnerability known as 'SearchLeak' (CVE-2026-42824) was discovered in Microsoft 365 Copilot. This flaw allowed attackers to craft malicious links that, when accessed by a user, could exfiltrate sensitive data such as emails, meeting notes, and documents from OneDrive and SharePoint. The attack exploited a parameter-to-prompt injection (P2P) technique, enabling unauthorized data disclosure over the network. Microsoft promptly addressed the issue by releasing a patch to mitigate the vulnerability. The 'SearchLeak' incident underscores the evolving nature of AI-driven cyber threats, particularly those targeting large language model (LLM) systems integrated into enterprise environments. It highlights the necessity for organizations to implement robust security measures, including prompt isolation and output sanitization, to protect against sophisticated prompt-injection attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
EvilTokens: The Phishing Service That Bypasses MFA Without Stealing Passwords
Impact· HIGH

EvilTokens: The Phishing Service That Bypasses MFA Without Stealing Passwords

In early 2026, the EvilTokens Phishing-as-a-Service platform emerged, exploiting the OAuth 2.0 device authorization grant flow to compromise over 340 Microsoft 365 organizations across multiple countries within five weeks. This method bypasses traditional password theft by tricking users into completing legitimate multi-factor authentication (MFA) processes on genuine Microsoft login pages, thereby granting attackers access tokens without raising typical security alarms. The attackers then gain persistent access to corporate emails, files, and other sensitive resources, facilitating data exfiltration and business email compromise (BEC) attacks. This incident underscores the evolving sophistication of phishing techniques that render conventional MFA defenses insufficient. Organizations must reassess their security protocols to address these advanced threats, emphasizing the need for continuous monitoring and user education on emerging phishing tactics.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft 365 Copilot 'SearchLeak' Vulnerability (CVE-2026-42824) Exposes Sensitive Data
Impact· HIGH

Microsoft 365 Copilot 'SearchLeak' Vulnerability (CVE-2026-42824) Exposes Sensitive Data

In June 2026, a critical vulnerability chain known as 'SearchLeak' was discovered in Microsoft 365 Copilot Enterprise, identified as CVE-2026-42824. This exploit allowed attackers to steal sensitive data from users' mailboxes, OneDrive, and SharePoint accounts through specially crafted URLs. The attack combined a parameter-to-prompt injection, an HTML rendering race condition, and a content-security-policy bypass enabled by Bing server-side request forgery. Microsoft addressed this vulnerability at the beginning of June 2026, assigning it a critical severity rating. The 'SearchLeak' incident underscores the evolving nature of cyber threats targeting AI-integrated enterprise tools. It highlights the necessity for organizations to implement robust security measures, conduct regular vulnerability assessments, and stay informed about emerging attack vectors to protect sensitive data effectively.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft 365 Copilot 'SearchLeak' Vulnerability Exposes Sensitive Data
Impact· HIGH

Microsoft 365 Copilot 'SearchLeak' Vulnerability Exposes Sensitive Data

In June 2026, Varonis Threat Labs identified a critical vulnerability in Microsoft 365 Copilot, termed 'SearchLeak'. This flaw allowed attackers to craft a single-click link that, when accessed by a user, could exfiltrate sensitive data such as emails, calendar details, and indexed files without any further interaction. The attack exploited a combination of AI prompt injection and web vulnerabilities, enabling unauthorized access to a user's Microsoft Graph data. Microsoft assigned CVE-2026-42824 to this issue and has since mitigated the flaw on its backend, with no known exploitation in the wild. This incident underscores the evolving nature of cyber threats targeting AI-integrated platforms. As organizations increasingly adopt AI-driven tools, it is imperative to implement robust security measures to prevent similar vulnerabilities. Continuous monitoring and prompt patching are essential to safeguard sensitive information against emerging attack vectors.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Unveiling App.MenuItem: A New Forensic Artifact in macOS Tahoe 26
Impact· LOW

Unveiling App.MenuItem: A New Forensic Artifact in macOS Tahoe 26

In June 2026, researchers identified a new artifact in macOS Tahoe 26, named App.MenuItem, which logs specific menu selections made by users across the operating system. This artifact provides a detailed record of user actions, such as compressing files or emptying the trash, offering critical context for forensic investigations. Located at ~/Library/Biome/streams/restricted/App.MenuItem/local, the artifact contains SEGB-encapsulated protobuf entries that require specific tools to parse. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/?_wpnonce=c8aaaf1bea&lg=en&pdf=download&utm_source=openai)) The discovery of App.MenuItem is significant for digital forensics, as it allows examiners to reconstruct user workflows with greater precision. By capturing exact menu choices and timestamps, investigators can gain insights into user intent and actions, enhancing the accuracy of forensic analyses. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/?_wpnonce=c8aaaf1bea&lg=en&pdf=download&utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports